MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c11514fce0720af2328f702e0a42aaea3b9d4ef635de46d638a9ca0629e5f75d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 14
| SHA256 hash: | c11514fce0720af2328f702e0a42aaea3b9d4ef635de46d638a9ca0629e5f75d |
|---|---|
| SHA3-384 hash: | 6b9db0af0c3c234b77e2cb1b090c0bddaea2f1e2b1c899785b3fda20f3d3f22ef3debbb26c1570dae8d300f0b740a635 |
| SHA1 hash: | 9688fc202f4f684f3ea065a73fe4016756e9ed8d |
| MD5 hash: | 64895cba9786ff965555f5308f7abd95 |
| humanhash: | green-venus-ink-eight |
| File name: | 08052023_dekont.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 601'088 bytes |
| First seen: | 2023-05-08 12:58:04 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:Ge+MhSIJWKr9tiJO8ht/ha9pUtdBwZMe/B6CgD4KkY:RhdQUgxPp39wgLkY |
| Threatray | 2'761 similar samples on MalwareBazaar |
| TLSH | T130D4025573B68F60F9758BF00A38B44003B234A799F0E65C0DE5A1CE2EE6F501AD5B6B |
| TrID | 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.0% (.EXE) Win64 Executable (generic) (10523/12/4) 6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.2% (.EXE) Win32 Executable (generic) (4505/5/1) 1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Reporter | |
| Tags: | exe FormBook geo TUR |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
fd0c237241cf1dd94f69484051725c5c791425fba130a5dadc427069e8b367cd
b47f0c9d2511489e546b2ee97ba405868eade9a380bb43ffbba62ccf9469cb28
c370659751fff9888445826997052a9a734c3619098c05347774ab4d3f7e1e4a
1e2470cf5042f4ff269c98c7a33dd27ca36ddeed91d9fb18df591f40a2d18131
1cdde22ebe2251b7dc0678e7a6a7911384565312929a39976a46154272bfb075
70e6864d836f4750789712dcb97587a60c5317e40ec5bccdbebff3c0fbfd7967
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.